Security Advisory Desk
unratedQCS priority 70/100Oracle

CVE-2026-21962: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

A security weakness in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in lets unauthorized users access or change important data. They might add, delete, or modify critical information without permission, risking data loss or theft.

Published 24/8/2026, 12:00:00 amVerified 1/9/2026, 12:09:07 amRevision 1
Oracle unrated network security advisory visual

In plain language

What this advisory means

A security weakness in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in lets unauthorized users access or change important data. They might add, delete, or modify critical information without permission, risking data loss or theft.

Technical explanation

How the issue affects the environment

The vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in is an improper access control issue (CWE-284). This flaw allows attackers to bypass security restrictions, granting unauthorized create, delete, or modify permissions on critical data managed by these services. Exploitation can lead to complete unauthorized access to all data accessible via these components, severely impacting system integrity and confidentiality.

Operational impact

Why teams should care

If exploited, this vulnerability can cause unauthorized data manipulation or full data exposure within Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in environments. This may result in data breaches, operational disruption, loss of trust, and potential regulatory compliance issues for organizations relying on these products.

Immediate action

Organizations should apply vendor-provided mitigations promptly following Oracle's instructions and comply with CISA’s Binding Operational Directive 26-04 (BOD 26-04) for prioritizing security updates based on risk. If mitigations are not available, stakeholders should discontinue product use or follow BOD 26-04 guidelines for cloud services. Continuous evaluation of internet exposure for affected assets is crucial.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Oracle reported an improper access control vulnerability in its HTTP Server and Weblogic Server Proxy Plug-in.
  • CISA listed CVE-2026-21962 in its Known Exploited Vulnerabilities Catalog on 2026-08-24.
  • CISA advises applying vendor mitigations per BOD 26-04 guidance.
  • No fixed versions are specified by the source.
  • Exploitation status: vulnerability is actively exploited, ransomware use unknown.
  • Forensic triage required per CISA guidance.

Authoritative reference

CISA Known Exploited Vulnerabilities

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source